Occupational health and safety audit

An occupational health and safety audit is a systematic, documented, and objective examination of an organization’s prevention system to verify its proper implementation, effectiveness, and compliance with regulations. In Spain, there is a mandatory regulatory audit for companies that manage their own prevention programs; alongside this, internal audits and certification audits for management systems such as ISO 45001 also exist, each with different purposes and legal implications.

In short

The occupational health and safety audit examines whether the prevention system is implemented, effective, and compliant with regulations. In Spain, it is mandatory and external for companies with their own prevention resources, and is carried out every four years (two years for activities listed in Annex I); internal and certification audits are voluntary and do not replace it.

Content
  1. What is a workplace safety and health audit?
  2. Differences between regulatory audit, internal audit and certification
  3. How is the regulatory audit performed?
  4. Report content and elements to be audited
  5. Common errors and quality criteria
  6. Practical example
  7. Regulatory framework in Spain
  8. Related concepts
  9. On the blog
  10. References

A–Z dictionary →

What is a workplace safety and health audit?

Article 30.6 of Law 31/1995 establishes that employers who have not contracted their prevention services with a specialized entity must submit their prevention system to an external audit or evaluation. Royal Decree 39/1997 defines this as a management tool that aims to accurately reflect the prevention system, assessing its effectiveness and identifying deficiencies that could lead to non-compliance, in order to enable the adoption of decisions aimed at its improvement and enhancement.

The regulatory audit verifies how the risk assessment was carried out, whether the type and planning of preventive activities comply with regulations and the assessment, whether the company’s own or contracted resources are adequate and sufficient, and whether prevention is integrated into the company’s overall management system. It must be performed by a person or entity authorized by the labor authority, using the methodology, independence, and report content established by the Regulations.

Beyond legal requirements, many organizations conduct internal audits of their management systems and third-party audits to obtain or maintain certifications. These audits are voluntary, do not replace mandatory audits, and their results have no bearing on labor authorities, although they help keep the system active between mandatory audits.

Differences between regulatory audit, internal audit and certification

The term audit applies to three processes with different rules.

  • Mandatory occupational health and safety audit. This audit is required in Spain for companies with their own occupational health and safety service or with designated workers who do not outsource all their activities. It is carried out by an authorized entity, follows the regulations, and its report must be kept available for the labor authority and workers’ representatives.
  • Internal audit. A review that the organization itself conducts of its system using its own criteria or a reference standard. It is voluntary, serves for continuous improvement, and does not certify legal compliance.
  • Certification audit. Evaluation by an accredited certification body against a standard such as ISO 45001. It is voluntary, verifies conformity with the standard, and does not exempt you from a mandatory regulatory audit.

Practical rule: If the company has its own preventative resources, it needs the mandatory audit even if it is certified; if it contracts all prevention services out to an external provider, it is not obligated to have one, but can voluntarily undergo an audit. An ISO 45001 certificate does not replace the mandatory audit report.

How is the regulatory audit performed?

The Prevention Services Regulations establish the scope, frequency, and content of the report. The first audit must be carried out within twelve months of the date on which the preventive activity plan is available, and repeated every four years, or every two years if the company carries out activities listed in Annex I; furthermore, it must be repeated when required by the labor authority in light of accident rates or other circumstances.

The usual process includes:

  1. Planning: definition of the scope (centers, activities, preventive modality), of the audit team and of the schedule, with consultation with the workers’ representatives.
  2. Document analysis: prevention plan, risk assessment, planning, concerts, prevention service report, training, health surveillance, coordination of activities and accident investigation.
  3. Verification at the center: interviews with management, supervisors, workers and their representatives, observation of positions and verification that the planned measures are implemented.
  4. Integration assessment: verifying that preventive functions are exercised at all levels and that company procedures incorporate prevention.
  5. Report: description of the system, methodology, results, deficiencies detected and conclusions on effectiveness, signed by the auditor and with the formalities of the Regulation.
  6. Follow-up: the company must incorporate the deficiencies into the planning, correct them and keep the report for the next audit and for the labor authority.

Companies with up to 50 employees without activities listed in Annex I may be exempt by notifying the labor authority as provided in Annex II of the Regulation, unless the authority decides otherwise due to the dangerousness of the activity or the accident rate.

Report content and elements to be audited

Article 31 of the Regulation sets out the minimum content of the audit report. In practice, the auditor examines:

  • Integration of prevention. Prevention plan, roles and responsibilities, communication and participation channels.
  • Risk assessment. Methodology, scope, updates, particularly vulnerable individuals, and review in the event of damage or changes.
  • Planning and monitoring. Measures, deadlines, responsible parties, resources, and evidence of implementation and verification.
  • Preventive organization. Adequacy and sufficiency of own resources and agreements, training of technicians and health activity.
  • Cross-cutting activities. Information and training, emergencies, health surveillance, coordination of activities, control of equipment and PPE, accident investigation.
  • Records and documentation. Mandatory documentation of article 23 of Law 31/1995 and traceability of actions.

The report must describe the system, methodology, results and conclusions, and identify the deficiencies detected and the recommendations for their correction, without the auditor being able to maintain commercial or other ties that compromise their independence.

Common errors and quality criteria

The most common shortcomings in regulatory auditing are:

  1. Failure to identify the obligation to be audited when establishing an in-house service or designating workers for part of the preventive activity.
  2. Exceeding the legal deadlines between audits or not carrying out the first one within twelve months of planning.
  3. Confusing ISO 45001 certification with the regulatory audit and disregarding the latter.
  4. Receive the report and do not transfer the deficiencies to the planning or correct them.
  5. Contracting audits with unauthorized entities or entities that are not independent from the external prevention service.
  6. Not informing or consulting the workers’ representatives, who should be aware of the report.

A useful audit is recognized because it produces a concrete report, with verifiable and prioritized deficiencies, which the company incorporates into its planning and closes before the next audit.

Practical example

Situation: a distribution company with 320 people, its own prevention service with two specialties and an external contract for the rest, faces its second regulatory audit.

  • Scope. All centers and activities; verification of the preventive organization, the workplace risk assessment, the planning and the agreed health activity.
  • Main findings. Preventive functions of warehouse managers not exercised in practice; planning with overdue measures without rescheduling; coordination of activities with carriers based on generic documentation.
  • Resulting measures. Review of the prevention plan and specific training for managers; rescheduling of measures with those responsible and budget; new coordination procedure with written instructions for each center.
  • Follow-up. Incorporation of deficiencies into planning with deadlines, internal verification at six months and retention of the report for the labor authority and for the next audit in four years.

Regulatory framework in Spain

OSH management system audits according to ISO 45001 are voluntary and international and are carried out by accredited certification bodies; in Latin America, some countries require periodic audits or self-assessments of the management system (for example, the minimum standards of the SG-SST in Colombia), with their own rules that do not coincide with the Spanish regulatory audit.

Related concepts

On the blog

References

  1. Official State Gazette. Law 31/1995, of November 8, on Occupational Risk Prevention, Articles 23, 30 and 39. 1995, current consolidated text. Official source
  2. Official State Gazette. Royal Decree 39/1997, of January 17, Regulation of Prevention Services, Articles 29 to 33 bis. 1997, current consolidated text. Official source
  3. Official State Gazette. Order TIN/2504/2010, of September 20, on the accreditation of specialized entities as prevention services, report of preventive activities and authorization of audits. 2010, current consolidated text. Official source
  4. National Institute for Occupational Safety and Health. Regulations on integration, prevention plan, and audits. Current consultation in 2026. Official source
  5. National Institute for Occupational Safety and Health. Technical guide for integrating occupational risk prevention into the company’s general management system. 2008. Official source

Editorial information

Publication date: August 30, 2026 .

Editorial Manager: Sabentis Editorial Team .

Editorial review by Pablo Rodríguez LinkedIn

Executive Vice President of the ORP International Foundation and Chief Financial Officer of Sabentis.

Request a Demo

Discover all that Sabentis can do for your organization.

Try Sabentis

request a demo
stars 5
GetApp Software Advice Capterra